
John Emil Youhana
Group Senior SOC Analyst - Tier 2 Incident Responder at EFG Holding
Rod Alfarag, Cairo, EgyptWork Experience
Group Senior SOC Analyst - Tier 2 Incident ResponderFull Time
EFG Holding
Sep 2023 - Present -1 yr, 9 months
Egypt , Cairo
- Job Details:- Mentor level 1 analysts and act as an escalation point to improve detection capability within the SOC. - Conduct digital forensics Investigation for multiple Incident types such as Fraud, Ransomware, Cyber attacks and incidents. - Use a range of security tools and technologies to identify and respond to security threats. - Provide regular updates on incident response activities. - Provide deep investigation of escalated security incidents and DFIR Analysis. - Develop and maintain incident response playbooks and procedures. - Create and tune the SIEM rules to improve detection capability. - Perform threat hunting based on TTPs of specific threat actors and Data sources for proactive detection. - Perform POC on various security solutions to assess their capabilities and ascertain their suitability for our environment. - Collaborate with other teams to ensure security incidents are resolved in a timely and effective manner. - Investigate and analyze malicious phishing emails, domains and IPs and take proper action based on IOCs extracted from analysis.
SOC Analyst - Tier 1Full Time
Commercial International Bank
Mar 2022 - Aug 2023 -1 yr, 5 months
Egypt , Cairo
- Job Details:- Detect, classify, and report incidents to either escalate to triage team or close the event to ensure the root cause of the incident. - Perform analysis of log files to investigate the events to identify the root cause of the incident. - Recommend tuning SIEM filters and correlation rules to continuously improve monitoring and detection. - Develop scripts to automate repetitive tasks and reports. - Identify security risks and communicate escalations throughout the incidents per the SOC processes. - Monitor all log sources heart beat and report/investigate issues to ensure maintaining healthy logs to avoid any failure of data collection and impacting the core SOC monitoring function. - Performing vulnerability scanning & patch management to ensure all organization assets is patched properly. - Investigate and analyze malicious phishing emails, domains and IPs and recommend proper action based on IOCs extract analysis. - Monitor security intelligence feeds to track various APTs, malware families and campaigns to keep up with their TTPs. - Evaluating and recommending security solutions tuning to ensure better prevention.
Incident Management SpecialistFull Time
- Job Details:- Provide technical point of contact for customers’ incidents. - Owns the resolution responsibility of the reported customer incidents either solely or with the help/intervention of other teams. - Diagnose fault-related incidents by effectively utilising software diagnostics and other network/product utility programs. - Document all troubleshooting and incident management actions via the electronic incident management system in a timely manner. - Perform technical escalations to different Problem Management teams in line with company procedure and case/incident excellence. - Perform and own technical management escalations in line with company procedure and case excellence policy. - Obtain and document data integrity issues and ensure getting valid Reason for Outage (RFO) when applicable and to note it in detail and Gain agreement to incident closure by customer or Service desk representative.
Systems EngineerFull Time
- Job Details:- Design, implement, install, configure & Troubleshooting Microsoft windows server 2008/2012 and Linux server - Design, implement, maintain, administer &Troubleshoot Vsphere and VMware infrastructure. - Troubleshooting and maintenance Active Directory, DNS, IIS, DHCP, WINS&RAS. - Managing Domains and trusts with Active Directory, DNS, DHCP. - Implement Security Issues with Group Policies. - Design, implement, maintain, administer & Troubleshoot SharePoint 2010. - Secure and configure mails with EXCHANGE SERVER 2010 and troubleshooting it. - Implementing, Managing & Monitoring Network Devices. - Making data Backup, Restore activities, and Testing Backup. - Administering backup application (VEEAM) - SQL Server 2008, SQL Server 2012 development and administration - Dealing with SQL Databases and ODBC connection with Microsoft Access. - Manage RAID configuration in HP Proliant Serves G5, G6, and G7.
Education
Bachelor's Degree in Computer Science
Ain Shams University (ASU)Jan 2016 - Jan 2020 - 4 yr
High School - Thanaweya Amma
Ahd Gedid Language SchoolJan 2016
Activities
Problem Solver at ACM
Student Activity
Oct 2016 - Jan 2017 -3 months
Skills
- Software Testing
- Cyber Security
- C#
- CCNA
- Information Technology (IT)
- Cybersecurity
- .Net
- Information Security
- C
- Python
View More
Languages
Arabic
FluentEnglish
FluentFrench
Intermediate
Training & Certifications
eLearnSecurity Certified Malware Analysis Professional(eCMAP)
eLearnSecurity·2023